Manager Platform Security
Richmond Hill - Canada
Job Summary
The Manager of Platform Security is responsible for leading a team of security engineers focused on the security of the Paymentus SaaS platform including web applications RESTful APIs cloud-native services containerized workloads serverless functions and AI-enabled application components. This role owns the execution of application and platform security engineering practices across the software development lifecycle and partners closely with Engineering Product DevOps Cloud Infrastructure Compliance and Security Operations to identify prioritize and remediate security risks before they impact Paymentus customers partners or regulated payment environments.
The successful candidate must combine strong people leadership with deep hands-on technical expertise. This is not a purely governance or advisory role. The individual must be capable of reviewing application architecture assessing source code and API implementations challenging insecure design decisions guiding engineers through secure remediation and building scalable security controls for modern SaaS platforms.
- Lead manage mentor and develop a team of platform and application security engineers responsible for securing the Paymentus SaaS platform.
- Build and mature the platform security program across application security API security cloud security container security Kubernetes security serverless security and AI application security.
- Partner with software engineering teams to embed security into the full SDLC including requirements architecture design reviews threat modeling secure coding automated testing deployment monitoring and remediation.
- Provide hands-on technical leadership for security reviews of applications and services written primarily in Java NodeJS Python and Golang.
- Assess and guide security design for applications and frameworks including Spring Struts Express Flask Django FastAPI LiteLLM and related open-source and commercial frameworks.
- Review and advise on secure configuration and deployment patterns for application servers and web infrastructure including Tomcat JBoss nginx reverse proxies gateways and edge delivery services.
- Lead security assessment and control development for public cloud environments across AWS GCP and Azure including identity and access management network controls encryption secrets management workload isolation logging and detection capabilities.
- Define and enforce security standards for Kubernetes containerized workloads container registries CI/CD pipelines infrastructure as code admission controls service mesh patterns and runtime security.
- Define and enforce security standards for serverless technologies including secure function design least-privilege execution roles event-source validation dependency control logging and abuse prevention.
- Drive secure architecture and security control reviews for RESTful APIs internal APIs partner APIs authentication flows authorization models service-to-service communication rate limiting input validation API gateways and abuse-prevention controls.
- Establish and mature security practices aligned with modern application security guidance including OWASP Top 10 OWASP API Security Top 10 and OWASP Top 10 for Large Language Model Applications.
- Lead security risk assessments for AI-enabled application components including prompt injection insecure output handling sensitive information disclosure model abuse excessive agency insecure plugin and tool integrations data leakage and AI supply chain risks.
- Develop secure design patterns and engineering guardrails for applications using LLM gateways model orchestration layers retrieval-augmented generation AI agents and third-party AI services.
- Own and improve application security testing capabilities including SAST DAST SCA container image scanning IaC scanning secrets detection API security testing dependency governance and manual security reviews.
- Ensure security tooling is effectively integrated into CI/CD pipelines with risk-based gates actionable findings developer-friendly feedback loops and measurable remediation outcomes.
- Lead the application vulnerability management process for the platform including triage severity validation exploitability analysis remediation guidance exception review SLA tracking and executive reporting.
- Partner with Engineering and Product leadership to prioritize security work based on business risk customer impact regulatory obligations exploitability and platform architecture.
- Support penetration testing red team exercises bug bounty intake customer security reviews and independent assessments related to the Paymentus platform.
- Collaborate with Security Operations and Incident Response teams on application-layer detections attack-path analysis logging requirements incident investigations and post-incident remediation.
- Develop and maintain platform security standards secure coding guidelines architecture patterns control baselines and security review procedures.
- Provide technical consultations on CDN WAF bot mitigation API protection DDoS protection caching edge security and traffic management controls using technologies such as Cloudflare and Fastly.
- Establish metrics and reporting for platform security posture including vulnerability trends remediation performance secure SDLC adoption security testing coverage risk exceptions and engineering engagement.
- Support compliance and audit obligations relevant to a publicly traded fintech and payment technology company including PCI DSS SOC 2 SOX-related technology controls privacy obligations customer security commitments and internal security policies.
- Attract hire develop and retain high-performing security engineering talent.
- Keep current with emerging application security cloud security AI security API security software supply chain and attacker tradecraft trends and translate those trends into practical improvements for the Paymentus platform.
This role has direct supervisory responsibility for a team of security engineers. Responsibilities include hiring onboarding performance management coaching technical mentorship career development workload prioritization project delivery and talent retention. The Manager of Platform Security is expected to build a strong engineering-oriented security culture that balances risk reduction developer enablement operational excellence and business velocity.
- Bachelors Degree in Computer Science Software Engineering Computer Engineering Information Security or a related technical field or equivalent practical experience.
- 8 years of combined experience in software engineering application security product security platform security cloud security or security engineering.
- 3 years of experience managing or technically leading security engineers software engineers or platform engineering teams.
- Extensive hands-on software development experience in one or more of the following languages: Java NodeJS Python Golang.
- Deep technical knowledge of modern web application architecture SaaS platforms microservices distributed systems RESTful APIs authentication authorization session management secure data handling and service-to-service communication.
- Strong knowledge of application security vulnerabilities and secure remediation patterns including injection flaws broken access control authentication weaknesses insecure deserialization SSRF XXE XSS CSRF business logic flaws insecure file handling and supply chain risks.
- Strong knowledge of API security risks including broken object-level authorization broken function-level authorization excessive data exposure mass assignment unrestricted resource consumption improper inventory management and unsafe API integrations.
- Strong knowledge of AI and LLM application security risks including prompt injection insecure output handling sensitive data exposure model misuse insecure tool use plugin risk excessive agency and AI supply chain concerns.
- Hands-on experience securing cloud environments in one or more major public cloud platforms: AWS GCP Azure.
- Hands-on experience with Kubernetes containers container registries image hardening workload identity network policies secrets management runtime controls and deployment security.
- Experience securing CI/CD pipelines and developer workflows including source control build systems artifact repositories automated testing release gates and infrastructure as code.
- Experience with security testing tools and practices including SAST DAST SCA container scanning IaC scanning secrets scanning API testing manual code review and threat modeling.
- Experience working with Engineering and Product teams to resolve complex security issues without unnecessarily blocking delivery.
- Strong analytical skills with the ability to quickly identify root cause exploitability compensating controls and appropriate remediation paths.
- Strong written and verbal communication skills including the ability to explain technical security issues to engineers and risk-based business impact to executives.
- Strong organizational and prioritization skills including experience delivering multiple concurrent security initiatives in a fast-moving engineering environment.
- Experience working in fintech payments banking financial services or another highly regulated SaaS environment.
- Experience with PCI DSS SOC 2 SOX technology controls NIST CSF ISO 27001 or similar control frameworks.
- Experience with payment systems payment processing tokenization cardholder data environments fraud controls or high-volume transaction platforms.
- Experience with CDN WAF bot mitigation rate limiting API gateway and edge security platforms such as Cloudflare and Fastly.
- Experience with application servers and runtime platforms such as Tomcat JBoss nginx JVM-based applications NodeJS services Python services and Go services.
- Experience with frameworks and platforms such as Spring Struts Express LiteLLM and modern LLM integration frameworks.
- Experience developing security paved roads reusable secure libraries shared platform controls secure service templates policy-as-code or developer self-service security capabilities.
- Experience building security metrics executive dashboards remediation scorecards and risk-based reporting.
- Relevant certifications such as CISSP CSSLP CCSP AWS Security Specialty Google Professional Cloud Security Engineer Azure Security Engineer CKS CKAD OSWE GWAPT GWEB or equivalent practical experience.
This job operates in a professional office and technology environment. This role routinely uses standard office and engineering equipment including laptop computers collaboration tools cloud platforms security platforms source code repositories ticketing systems and communication systems. The role requires frequent collaboration with geographically distributed teams and may involve participation in security incident response urgent vulnerability remediation production risk reviews and executive briefings.
While performing the duties of this job the employee is regularly required to talk hear type read and view computer screens for extended periods. Specific vision abilities required by this job include close vision and the ability to adjust focus. The employee may occasionally be required to stand walk reach with hands and arms lift files or equipment open filing cabinets bend or stand on a stool as necessary. The employee may occasionally be required to lift up to 25 lbs.
This is a full-time position. Days and hours of work are generally Monday through Friday during normal business hours. Occasional evening weekend or on-call work may be required based on business needs security incidents critical vulnerabilities production releases audit deadlines or customer commitments.
Minimal travel is expected. Occasional travel may be required for company meetings team events customer security discussions conferences audits or vendor engagements.
This job description is not designed to cover or contain a comprehensive listing of all activities duties or responsibilities required of the employee. Duties responsibilities and activities may change at any time with or without notice.
Paymentus is an equal opportunity employer. We enthusiastically accept our responsibility to make employment decisions without regard to race religious creed color age sex sexual orientation national origin ancestry citizenship status religion marital status disability military service or veteran status genetic information medical condition including medical characteristics or any other classification protected by applicable federal state provincial and local laws and ordinances. Our management is dedicated to ensuring the fulfillment of this policy with respect to hiring placement promotion transfer demotion layoff termination recruitment advertising pay and other forms of compensation training and general treatment during employment.
Paymentus recognizes and supports its obligation to endeavor to accommodate job applicants and employees with known physical or mental disabilities who are able to perform the essential functions of the position with or without reasonable accommodation. Paymentus will endeavor to provide reasonable accommodations to otherwise qualified job applicants and employees with known physical or mental disabilities unless doing so would impose an undue hardship on the Company or pose a direct threat of substantial harm to the employee or others.
An applicant or employee who believes he or she needs a reasonable accommodation of a disability should discuss the need for possible accommodation with the Human Resources Department or his or her direct supervisor.
Required Experience:
Manager
About Company
Paymentus delivers secure, smart billing and payment solutions that boost engagement and on-time payments for businesses, governments, utilities, and more.